I found the following in my /var/log/messages

Dec 25 14:31:59 myhost portsentry[1413]: attackalert: UDP scan from host:
gateway/192.168.1.254 to UDP port: 53
Dec 25 14:31:59 myhost portsentry[1413]: attackalert: Host 192.168.1.254 has
been blocked via wrappers with string: "ALL: 192.168.1.254"
Dec 25 14:31:59 myhost portsentry[1413]: attackalert: Host 192.168.1.254 has
been blocked via dropped route using command: "/sbin/ipchains -I input -s
192.168.1.254 -j DENY -l"


This is strange as the gateway is a cisco router, and my machine
doesnt run named. any comments? is this serious?


thanks
St.        
-- 
SLUG - Sydney Linux User Group Mailing List - http://slug.org.au/
More Info: http://lists.slug.org.au/listinfo/slug

Reply via email to